PT-2017-13083 · Open Networking Operating System · Onos
Publicado
2017-08-30
·
Atualizado
2022-05-13
·
CVE-2017-13763
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ONOS versions 1.8.0 through 1.10.0
Description
The issue is related to the lack of restriction on the amount of memory allocated, specifically due to the unlimited Netty payload size. This can lead to a potential denial of service, as seen in ONOS nodes timing out when attempting to connect to the cluster in a vm test cluster.
Recommendations
For ONOS version 1.8.0, consider restricting the Netty payload size to prevent excessive memory allocation.
For ONOS version 1.9.0, restrict the Netty payload size to minimize the risk of denial of service.
For ONOS version 1.10.0, limit the Netty payload size to prevent potential service disruptions.
Correção
Allocation of Resources Without Limits
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Onos